Notification of a cybersecurity event

HRS §431:3B-302, under Chapter 431.

HRS §431:3B-302

[§431:3B-302] Notification of a cybersecurity event. (a) Each licensee shall notify the commissioner as promptly as possible, but in no event later than three business days from a determination that a cybersecurity event impacting two hundred fifty or more consumers has occurred. If law enforcement officials instruct a licensee not to distribute information regarding a cybersecurity event, the licensee shall not be required to provide notification until instructed to do so by law enforcement officials. Notification shall be provided when either of the following criteria has been met:

(b) The licensee shall provide as much of the following information as possible and practicable and as promptly as possible:

(c) The licensee shall provide the information in electronic form as directed by the commissioner.

(d) The licensee shall have a continuing obligation to update and supplement initial and subsequent notifications to the commissioner regarding material changes to previously provided information concerning the cybersecurity event.

(e) This section shall not supersede any reporting requirements in chapter 487N. [L 2021, c 112, pt of §2]